FTPS only protects the session if the client validates the server's certificate and negotiates strong TLS. Many FTPS clients and scripts skip certificate validation or accept self-signed certificates, so an attacker in the network path presents their own certificate and intercepts the session, recovering the credentials and files. Deprecated ciphers and protocol versions allow a downgrade to a breakable or strippable channel.
# Enumerate the FTPS TLS configuration (protocols, ciphers, cert)
nmap -p 21 --script ssl-enum-ciphers,ftp-syst <target>
sslscan --starttls=ftp <target>:21
Exploitation notes#
- Clients that ignore certificate errors (common in automation and legacy GUIs) are interceptable with a self-signed cert on a man-in-the-middle position.
- Support for SSLv3, TLS 1.0, RC4, or 3DES flags a downgradeable or weak channel.
- Explicit FTPS (AUTH TLS) can sometimes be stripped if the client does not require encryption, falling back to cleartext FTP.